Researcher’s Copilot worm hides in Word docs and spreads unseen for 144 days
Curated by the Inblix editorial team
Håkon Måløy didn’t just find a vulnerability. He built a self-spreading worm that turns Microsoft Copilot against its users, and Microsoft has known about it for 144 days without shipping a fix.
The attack is almost laughably simple. An attacker hides malicious instructions in a Word document using white text on a white background at a tiny font size. A human reader sees nothing. But Copilot, which strips out color and font-size formatting before processing text, reads every word and obediently executes the commands. When someone uses that poisoned document as a source in Copilot, the hidden prompt injection fires, and the malicious instructions get copied into the new file. That file is now a carrier. Use it as a template, and the infection propagates further.
The real-world attack chain writes itself. A compromised market analysis gets posted to the web. An analyst downloads it, uses Copilot to generate a financial report, and unwittingly bakes the hidden instructions into their output. That report gets shared with the CFO, whose Copilot-generated summary pulls from the infected file, spreading the payload deeper into the organization. Måløy is withholding the actual payload text, but the mechanism alone is enough to make security teams uncomfortable.
Microsoft confirmed the behavior on March 31. Two attempted fixes failed. After nearly five months of silence, Måløy went public. AI researcher Andreas Kirsch had recently joked that he wished someone would build exactly this kind of worm to convince skeptics that AI security risks aren’t theoretical. Wish granted. Prompt injection remains the ghost in every LLM-powered product, and Copilot’s document-processing pipeline just handed attackers an automated delivery system that requires no user to click a suspicious link or enable a macro. The document looks clean. Copilot does the rest.
💡 Key Takeaways
- Malicious prompt injections can be hidden in Word documents using white-on-white text at tiny font sizes — invisible to humans but fully readable by Copilot.
- The attack self-propagates: when Copilot uses an infected document as a source, it copies the hidden instructions into the new file, turning it into a new carrier.
- Microsoft confirmed the vulnerability on March 31 and failed two fix attempts over 144 days, leaving the exploit unpatched at the time of publication.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.